发表机构
TU Wien; University of Klagenfurt(维也纳技术大学; 克雷格福大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
研究使用自主人工智能代理进行进攻性安全时的伦理问题,分析道德归因在多方的扩散及技术对利益相关者的影响,通过研究其不确定性等特性及攻防成本不对称性,为现有框架不适用于此情况提供分层建议。
AI 中文摘要
由语言模型驱动的自主代理正在重塑进攻性安全。与传统渗透测试工具不同,代理安全工具在三个维度上具有不确定性:行动源于非确定性策略,输出难以事前和事后解释,影响具有开放性,用户群体在规模和所需技能上不确定。这三个特性相互关联但不可相互推导,结合攻防结构成本不对称,促成了进攻能力的产业化。现有框架不适用于此,本文分析了使用自主人工智能代理进行进攻性安全时道德归因在用户、工具制造商和第三方之间如何扩散,并研究了该技术对利益相关者的影响并提供分层建议。
英文摘要
LLM-driven autonomous agents are reshaping offensive security. Unlike traditional penetration-testing tooling - deterministic, narrowly scoped, and operated by trained practitioners - agentic security tools exhibit indeterminacy along three independent dimensions. First, their actions are drawn from a non-deterministic policy whose outputs resist both ex-ante and ex-post explanation. This complicates incident attribution and pre-deployment safety reviews. Second, their impact is open-ended due to their non-deterministic actions, agency of utilized models, and opaque LLM supply-chains. Third, their user population is indeterminate in both size and required skill: the operating skill floor for using or developing offensive capabilities has dropped sharply. These three properties are linked thematically, but are not derivable from one another. Combined with the structural cost asymmetry between offense and defense, they enable the industrialization of offensive capability. The net short-term effect favors attackers, even if the same technology may, in the long run, democratize access to defensive practice. Existing dual-use cybersecurity and AI-ethics frameworks struggle to address this combination. Our work analyzes how moral attribution becomes diffuse between users, tool-makers, and third parties when employing autonomous AI agents for offensive security. We also examine the stakeholder impact of this technology and provide stratified recommendations.
Commentsaccepted at FAIEMA 2026